BIOC
Medium
✕
PowerShell downloads files via BITS
This PowerShell argument is often used to run commands with malicious intent.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: BITS Jobs (T1197)
Indicator:
Process action type = execution AND target process cmd = *start-bitstransfer* , *complete-bitstransfer* AND target process name = powershell.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows
Preventable: yes